Mail flow and connectors
Review inbound and outbound connectors, transport rules, accepted domains, relay assumptions, third-party gateway dependencies, and ownership of exceptional routing.
A focused Exchange Online security assessment covering mail flow, administrative and application access, protection settings, public email authentication, auditing, and operational ownership.
Coverage is adjusted for Exchange Online licensing, hybrid dependencies, accepted mail-flow design, third-party gateways, Microsoft Defender for Office 365 licensing, and the domains included in scope.
Review inbound and outbound connectors, transport rules, accepted domains, relay assumptions, third-party gateway dependencies, and ownership of exceptional routing.
Assess external forwarding controls, inbox-rule risk signals where available, shared and resource mailbox governance, delegates, Full Access, Send As, and Send on Behalf assignments.
Review Exchange administrative roles, role groups, service principals, application access controls where used, automation dependencies, and privileged operational paths.
Evaluate anti-spam, anti-malware, connection filtering, spoof handling, quarantine dependencies, and standard protection settings that apply to the licensed service.
Review SPF, DKIM, DMARC, Microsoft 365 DKIM selector records, alignment, reporting ownership, and the limits of conclusions drawn from public DNS.
Assess mailbox and administrative audit availability, alert and investigation paths, retention dependencies, change records, exception reviews, and ownership of messaging incidents.
Review forwarding, connectors, transport rules, delegates, applications, and exceptional routing against documented business need.
Identify administrative, delegated, shared-mailbox, and application access paths that need clearer scope, ownership, or periodic review.
Evaluate audit availability, alerting, retention dependencies, ownership, and the evidence path for suspicious forwarding, access, or mail-flow changes.
Confirm domains, mail gateways, hybrid elements, connectors, applications, privileged teams, regulated workflows, licensing, and known exceptions.
Collect agreed evidence for mail flow, forwarding, delegates, administration, applications, protection, email authentication, and audit controls.
Follow representative inbound, outbound, delegated, automated, and exceptional flows to resolve ownership, necessity, and control coverage.
Prioritize changes by exposure, business dependency, affected domains or mailboxes, investigation value, and operational change risk.
The standard assessment focuses on configuration, permissions, mail flow, protection settings, audit evidence, and operational records. It does not read ordinary mailbox content. Any exceptional content need would require explicit justification and authorization.
Exchange Online built-in protections and dependencies are reviewed as applicable. Advanced Microsoft Defender for Office 365 capabilities receive detailed treatment only where licensed and included; a dedicated Defender assessment is available.
Public email-authentication and mail-routing records can be reviewed alongside relevant Exchange Online configuration. Public DNS alone cannot establish the state of internal tenant controls.
Cloud-side connectors, mail flow, identities, and dependencies can be included by agreement. A deep review of on-premises Exchange servers, operating systems, and network infrastructure requires an explicitly expanded scope.
Go deeper on Safe Links, Safe Attachments, anti-phishing, submissions, investigation, response, and campaign visibility where licensed.
Prepare an evidence-led review of mail flow, forwarding, SMTP AUTH, connectors, auditing, and email authentication.
Check directional public SPF, DMARC, Microsoft 365 DKIM selector, DNSSEC, and mail-routing signals without tenant access.
Expand the review across identity, access, collaboration, endpoint, applications, and security operations.
Share the business trigger, relevant Microsoft 365 licensing, approximate environment size, and decision deadline. No credentials or tenant exports are needed for the first conversation.